Intigriti September 2026 Challenge, Critter Gallery
Vulnerability: Unauthenticated SQL injection (MySQL 8.0.46) in the base64-encoded pic parameter of /challenge.php, exploited with a single-column UNION SELECT to read the secret_vault table.
TL;DR
/c
blog.iliyadindar.site8 min read